<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>FWCore</title>
    <link>/</link>
    <description>Recent content on FWCore</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 31 Dec 2025 09:38:17 +0000</lastBuildDate>
    <atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to enable logging in 3x-ui?</title>
      <link>/posts/how-to-enable-logging-in-3x-ui-e5a9cd/</link>
      <pubDate>Wed, 31 Dec 2025 09:38:17 +0000</pubDate>
      <guid>/posts/how-to-enable-logging-in-3x-ui-e5a9cd/</guid>
      <description>&lt;p&gt;I want to enable logging for a proxy hosted with 3x-ui, how do I do that?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Abuse InfinityFree to Host Web Proxies for General Browsing</title>
      <link>/posts/abuse-infinityfree-to-host-web-proxies-for-general-browsing-c9e4ac/</link>
      <pubDate>Sun, 28 Dec 2025 02:20:39 +0000</pubDate>
      <guid>/posts/abuse-infinityfree-to-host-web-proxies-for-general-browsing-c9e4ac/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;It won’t be as secure, fast, or private as VLESS, VMess, etc., but if you really can’t get a client, this &lt;em&gt;might&lt;/em&gt; work.&lt;/p&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;YOU HAVE BEEN WARNED&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;things-you-need&#34;&gt;Things You Need&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Email&lt;/li&gt;&#xA;&lt;li&gt;Computer (a phone can be used, but it’s harder)&lt;/li&gt;&#xA;&lt;li&gt;A good internet connection&lt;/li&gt;&#xA;&lt;li&gt;A cup of coffee (optional ☕)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;1-download-php-proxy&#34;&gt;1. Download PHP-Proxy&lt;/h2&gt;&#xA;&lt;p&gt;Open this link:&#xA;&lt;a href=&#34;https://www.php-proxy.com&#34;&gt;https://www.php-proxy.com&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Then click the link under this text:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;For those who do not have access to shell, for example, people on a shared hosting environment, would need to download a pre-installed version of php-proxy, and then upload it to their web-server.&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Download the pre-installed ZIP file.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Best proxy cores to use right now</title>
      <link>/posts/best-proxy-cores-to-use-right-now-3111de/</link>
      <pubDate>Sat, 27 Dec 2025 12:53:01 +0000</pubDate>
      <guid>/posts/best-proxy-cores-to-use-right-now-3111de/</guid>
      <description>&lt;h2 id=&#34;best-proxy-cores-right-now&#34;&gt;Best Proxy Cores Right Now&lt;/h2&gt;&#xA;&lt;h3 id=&#34;1-sing-box&#34;&gt;1. Sing-box&lt;/h3&gt;&#xA;&lt;p&gt;Sing-box is a newer core with support for many protocols. However, when using the native apps on macOS and iOS, it is very difficult to configure. It’s better to use Sing-box through clients like &lt;strong&gt;v2rayN&lt;/strong&gt; and &lt;strong&gt;Throne&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Apparently, it does not support &lt;strong&gt;XTLS Reality&lt;/strong&gt;, as it is closed source.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h3 id=&#34;2-xray&#34;&gt;2. Xray&lt;/h3&gt;&#xA;&lt;p&gt;Xray is a fork of the V2Ray core with &lt;strong&gt;XTLS Reality&lt;/strong&gt; support added. However, it does not support &lt;strong&gt;Hysteria 2&lt;/strong&gt;.&#xA;This is a good core to use if you rely on &lt;strong&gt;XTLS Reality Vision&lt;/strong&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Speed Up GitHub in China</title>
      <link>/posts/speed-up-github-in-china-70e2a7/</link>
      <pubDate>Sat, 27 Dec 2025 12:10:04 +0000</pubDate>
      <guid>/posts/speed-up-github-in-china-70e2a7/</guid>
      <description>&lt;p&gt;To speed up GitHub in China, you have a few options:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;For raw content, some repositories provide a jsDelivr API, but it’s not guaranteed and updates less frequently.&lt;/li&gt;&#xA;&lt;li&gt;You can also clone the content onto Gitee, but this is subject to censorship.&lt;/li&gt;&#xA;&lt;li&gt;Another option is modifying your hosts file, which we’ll focus on today. This allows you to access GitHub more easily. Downloads may still be slow, but at least you can access GitHub and use additional methods to speed up downloads.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;1-edit-your-hosts-file&#34;&gt;1. Edit Your Hosts File&lt;/h3&gt;&#xA;&lt;p&gt;Open your hosts file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>About FWCore</title>
      <link>/about/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/about/</guid>
      <description>&lt;p&gt;FWCore (Firewall Core) is a forum focused on the technical aspects of blocking sites with firewalls, including platforms like Fortinet and national firewalls such as the Chinese GFW and Iran’s filtering systems.&lt;/p&gt;&#xA;&lt;p&gt;Guidelines:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Keep discussion technical; please avoid politics.&lt;/li&gt;&#xA;&lt;li&gt;You may ask for support, but share only non-sensitive details.&lt;/li&gt;&#xA;&lt;li&gt;Be respectful and keep conversations constructive.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Community Rules</title>
      <link>/posts/rules/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/posts/rules/</guid>
      <description>&lt;p&gt;Welcome to FWCore. Please follow these default rules:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Stay respectful: no harassment, hate speech, or personal attacks.&lt;/li&gt;&#xA;&lt;li&gt;Keep posts on-topic: align with FWCore themes and avoid spam.&lt;/li&gt;&#xA;&lt;li&gt;No sensitive data: don’t post secrets, personal info, or private logs.&lt;/li&gt;&#xA;&lt;li&gt;Cite sources when sharing claims or news.&lt;/li&gt;&#xA;&lt;li&gt;Use tags wisely: tag posts so readers can find them.&lt;/li&gt;&#xA;&lt;li&gt;One account per person; no impersonation.&lt;/li&gt;&#xA;&lt;li&gt;Moderation decisions are final; appeal politely if needed.&lt;/li&gt;&#xA;&lt;li&gt;Reports: flag issues via the moderation channel or contact mods directly.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Thanks for keeping the forum useful and safe.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction to GFWMass</title>
      <link>/posts/introduction-to-gfwmass/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/posts/introduction-to-gfwmass/</guid>
      <description>&lt;h2 id=&#34;what-is-gfwmass&#34;&gt;What is GFWMass?&lt;/h2&gt;&#xA;&lt;p&gt;GFWMass is a script that automates deploying up to 1,000 links to a single proxy.&lt;/p&gt;&#xA;&lt;p&gt;This can help increase the spread of proxies so a firewall is less likely to flag you for visiting one host repeatedly.&lt;/p&gt;&#xA;&lt;h2 id=&#34;architecture&#34;&gt;Architecture&lt;/h2&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Client → Cloudflare (cdn-47fh.example.com) → Caddy → Xray/VLESS → Internet&#xA;         Cloudflare (signup-hf33.example.com) ↗&#xA;         Cloudflare (api-92kl.example.com) ↗&#xA;         ... (hundreds more)&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;ol&gt;&#xA;&lt;li&gt;It generates realistic subdomains that represent real services.&lt;/li&gt;&#xA;&lt;li&gt;Adds them to Cloudflare via API and enables proxies so your origin IP stays hidden.&lt;/li&gt;&#xA;&lt;li&gt;Caddy handles TLS from Cloudflare using a wildcard certificate from certbot (can be replaced with Cloudflare origin certs if needed).&lt;/li&gt;&#xA;&lt;li&gt;Xray/VLESS over WebSocket (WS): single VLESS+WS endpoint serving all domains.&lt;/li&gt;&#xA;&lt;li&gt;Provides a &lt;code&gt;subscription.txt&lt;/code&gt; with base64-encoded VLESS links for all generated domains.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h2 id=&#34;prerequisites&#34;&gt;Prerequisites&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;A VPS with port 443 open.&lt;/li&gt;&#xA;&lt;li&gt;A domain name with Cloudflare DNS (a free one from digiplat works).&lt;/li&gt;&#xA;&lt;li&gt;Git installed and root access.&lt;/li&gt;&#xA;&lt;li&gt;Debian-based distro preferred (not tested on others).&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;h2 id=&#34;steps-to-deploy-gfwmass&#34;&gt;Steps to deploy GFWMass&lt;/h2&gt;&#xA;&lt;p&gt;Steps to deploy GFWMass&lt;/p&gt;</description>
    </item>
    <item>
      <title>Posting Guide</title>
      <link>/posts/posting-guide/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/posts/posting-guide/</guid>
      <description>&lt;p&gt;Quickstart (do these every time):&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Prepare your Markdown: clear title + short first paragraph (used as summary).&lt;/li&gt;&#xA;&lt;li&gt;Add your GitHub profile in the submit form so giscus shows your identity.&lt;/li&gt;&#xA;&lt;li&gt;Run the proof-of-work step; it may take ~2 minutes.&lt;/li&gt;&#xA;&lt;li&gt;Use 2–4 tags so readers can find your post.&lt;/li&gt;&#xA;&lt;li&gt;Expect moderation; posts queue until approved.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Quality and moderation tips:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Title: concise and descriptive; avoid clickbait.&lt;/li&gt;&#xA;&lt;li&gt;Body: start with a one- to two-sentence summary, then details.&lt;/li&gt;&#xA;&lt;li&gt;Tags: 2–4 relevant tags, lowercase.&lt;/li&gt;&#xA;&lt;li&gt;Links: prefer primary sources; add brief context for each link.&lt;/li&gt;&#xA;&lt;li&gt;Sensitive info: do not include secrets, personal data, or private logs.&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>Submit a Post</title>
      <link>/submit/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/submit/</guid>
      <description>&lt;p&gt;Your GitHub account is used for identity in giscus comments. Please include your GitHub profile link so readers can recognize you. All fields except tags are required. Submissions now require a short proof-of-work (PoW) before sending; it may take ~2 minutes depending on hardware.&lt;/p&gt;&#xA;&lt;form class=&#34;submit-form&#34; method=&#34;post&#34; action=&#34;https://fwcore-backend.lyu63651-8ca.workers.dev/submit&#34; accept-charset=&#34;UTF-8&#34; data-pow-difficulty=&#34;21&#34;&gt;&#xA;  &lt;input type=&#34;hidden&#34; name=&#34;form_type&#34; value=&#34;post&#34;&gt;&#xA;&lt;p&gt;&lt;label for=&#34;github-url&#34;&gt;GitHub profile URL *&lt;/label&gt;&#xA;&lt;input id=&#34;github-url&#34; name=&#34;github_url&#34; type=&#34;url&#34; required placeholder=&#34;https://github.com/yourname&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;label for=&#34;title&#34;&gt;Title *&lt;/label&gt;&#xA;&lt;input id=&#34;title&#34; name=&#34;title&#34; type=&#34;text&#34; required placeholder=&#34;Post title&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;label for=&#34;tags&#34;&gt;Tags (comma-separated)&lt;/label&gt;&#xA;&lt;input id=&#34;tags&#34; name=&#34;tags&#34; type=&#34;text&#34; placeholder=&#34;tag-one, tag-two&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;label for=&#34;body&#34;&gt;Content *&lt;/label&gt;&lt;/p&gt;&#xA;  &lt;textarea id=&#34;body&#34; name=&#34;body&#34; rows=&#34;10&#34; required placeholder=&#34;Write in Markdown&#34;&gt;&lt;/textarea&gt;&#xA;  &lt;input type=&#34;hidden&#34; id=&#34;pow-timestamp&#34; name=&#34;pow_timestamp&#34;&gt;&#xA;  &lt;input type=&#34;hidden&#34; id=&#34;pow-difficulty&#34; name=&#34;pow_difficulty&#34;&gt;&#xA;  &lt;input type=&#34;hidden&#34; id=&#34;pow-nonce&#34; name=&#34;pow_nonce&#34;&gt;&#xA;  &lt;input type=&#34;hidden&#34; id=&#34;pow-hash&#34; name=&#34;pow_hash&#34;&gt;&#xA;  &lt;div id=&#34;pow-status&#34; class=&#34;pow-status&#34;&gt;Proof of work not started.&lt;/div&gt;&#xA;&lt;p&gt;&lt;button type=&#34;submit&#34;&gt;Generate proof &amp;amp; submit&lt;/button&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>You Don&#39;t Need Reality</title>
      <link>/posts/you-dont-need-reality/</link>
      <pubDate>Sat, 27 Dec 2025 00:00:00 +0000</pubDate>
      <guid>/posts/you-dont-need-reality/</guid>
      <description>&lt;p&gt;Why?&lt;/p&gt;&#xA;&lt;p&gt;Technically any proxy protocol that uses TLS can SNI-spoof by presenting a self-signed cert for any domain. It will lack the padding of XTLS Reality flow, but if you need the characteristics of another proxy protocol, SNI spoofing without Reality is still possible.&lt;/p&gt;&#xA;&lt;p&gt;The one I recommend is Naive Proxy; it uses the Chromium stack, so the handshake is very close to a real browser.&lt;/p&gt;&#xA;&lt;p&gt;But it depends on your threat model: if you are worried about deep packet inspection, Reality is still better because it adds padding and obfuscation to the traffic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Search</title>
      <link>/search/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/search/</guid>
      <description>search</description>
    </item>
  </channel>
</rss>
